Nightcore (@nigh7c0r3) 's Twitter Profile
Nightcore

@nigh7c0r3

468

ID: 1738569564475334656

calendar_today23-12-2023 14:38:03

47 Tweet

11 Followers

610 Following

Coffin (@coffinxp7) 's Twitter Profile Photo

Just published a new article on bypassing live Cloudflare, ModSecurity, Fortinet, Akamai WAFs with SQL injection using Ghauri and Sqlmap. Don’t forget to read the Tips section for all methods and tricks that always worked for me. infosecwriteups.com/mastering-sqlm…

Swissky (@pentest_swissky) 's Twitter Profile Photo

Discover how the Fairy Law technique leverages Windows mitigation policies to bypass Endpoint Detection and Response (EDR) solutions. - Orange Cyberdefense orangecyberdefense.com/global/blog/cy…

PortSwigger Research (@portswiggerres) 's Twitter Profile Photo

Voting is now live for the top ten web hacking techniques of 2025! Grab a coffee, browse the 61 quality nominations and cast your vote on the most creative and ground-breaking techniques: portswigger.net/polls/top-10-w…

🇷🇴 cristi (@cristivlad25) 's Twitter Profile Photo

My JS surface mapper is now live in CAI (Alias Robotics). It's a tool for the web pentester agent that does JS analysis: github.com/aliasrobotics/…

André Baptista (@0xacb) 's Twitter Profile Photo

Manually going through multiple web archiving sites while hunting can be a tedious task. Here is a browser extension to help you do that quickly. chromewebstore.google.com/detail/web-arc… addons.mozilla.org/en-US/firefox/…

Sean Heelan (@seanhn) 's Twitter Profile Photo

Blog post: On the Coming Industrialisation of Exploit Generation with LLMs sean.heelan.io/2026/01/18/on-… TL;DR: I ran an experiment with GPT-5.2 and Opus 4.5 based agents to generate exploits for a zeroday QuickJS bug. They're pretty good at it. Code: github.com/SeanHeelan/ana…

Muqsit 𝕏 (@mqst_) 's Twitter Profile Photo

🤯A Really Awesome Guide on JavaScript Analysis for Pentesters Blog: kpwn.de/2023/05/javasc… Author: Konstantin #infosec

🤯A Really Awesome Guide on JavaScript Analysis for Pentesters 

Blog: kpwn.de/2023/05/javasc…

Author: Konstantin

#infosec
Omar Hasan 🇵🇸 (@mushroomwasp) 's Twitter Profile Photo

My Web challenge writeups from 0xL4ugh CTF v5👑🚩 1) pdf.exe Next.js DNS Rebinding → Python CRLF → pdfkit Injection mushroom.cat/ctf/nextjs-ssr… 2) gap Lodash RCE via JSON vs JS mismatch mushroom.cat/ctf/json-js-rc… Both include 0-days 👌 And take my word.. Lodash one is fun😉

My Web challenge writeups from <a href="/0xL4ugh/">0xL4ugh</a> CTF v5👑🚩

1) pdf.exe  
Next.js DNS Rebinding → Python CRLF → pdfkit Injection
mushroom.cat/ctf/nextjs-ssr…

2) gap  
Lodash RCE via JSON vs JS mismatch
mushroom.cat/ctf/json-js-rc…

Both include 0-days 👌
And take my word.. Lodash one is fun😉
FuzzingLabs (@fuzzinglabs) 's Twitter Profile Photo

🚀 Open-sourcing MCP Security Hub A growing collection of MCP servers bringing security tools to AI assistants Nmap, Ghidra, Nuclei, SQLMap, Hashcat... and we're just getting started Contribute your favorite tools 🛠️ ⭐ github.com/FuzzingLabs/mc…

gemini-cli (@geminicli) 's Twitter Profile Photo

Gemini CLI 🤝 OpenClaw🦞 Read below how Gemini CLI's Security extension helped identify and resolve a security vulnerability in OpenClaw. Gemini CLI then helped put up a PR which has since been merged. ✅ Read the details below👇

blackorbird (@blackorbird) 's Twitter Profile Photo

About A growing collection of #MCP servers bringing offensive security tools to AI assistants. Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more. github.com/FuzzingLabs/mc…

About A growing collection of #MCP servers bringing offensive security tools to AI assistants. 
Nmap, Ghidra, Nuclei, SQLMap, Hashcat and more.
github.com/FuzzingLabs/mc…
Aituglo (@aituglo) 's Twitter Profile Photo

I've been doing bug bounty for years. I just published a long piece on what it actually feels like in 2026, and why something fundamental has shifted. aituglo.com/state-of-bug-b… Would love to get your feedback on it here on X or directly on the blog